Red Hat Security Advisory: OpenShift Container Platform 4.13.29 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products69
- Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:05d6234e1a633a3f4031c577c915da75cece186dcd270f89447a03f1fd250a1a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:1670b7ed6745cfab81e2f472e9e77834e0fb6dc792b017bccda1217403dc0247_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:f83f933fe00b8434456d7924e07f07a82ae38991270945fe96770982bdc414e7_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:fbe0e1f721cbc7db4f46191f2e96cd3e439d4de6af3e4c3656e90b32d6cb2da2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:473cce3ee81558458beb6778df4fad6024a75ff3ce212fbc9848d30732bfe0dd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:c401686e9a0c234f590cb505372ba94302b9a0e0b73867e39a0e12426ca6e6ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:cf3ee30fc23923f027f97f6611abd2eeb21164aa65697445664a6f860929f7e0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:db1d60dd61f746fdc09a73c6520a2e32590bfbd22417f8d379d6a72a3b7505b7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:16e8bd6a4bfc6cac55541cbf038c475c54c8207ac82212766368d6df363967b0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:59b8105f8c827c6954f0ccb97321f851f387327ab7af6cea58d9fba71ceeac0b_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:66d8c54aa10c766124c332a0203e717f7f8b120031b5933e977f5b12644dd11a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:b2e2bd59321c4301a2ee202090bf40b230ce7a1ee0871f9b0a30be9b37a8882d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:7a895374b2289119947ac54b49c34c2abd44e7f108411b65a0181e9965d5205f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:f9fa6a423bc75e9864c2acef175a6cc5494d6175c70c9145c56b6eea5c953f2f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-network-operator@sha256:434ad23d0d405b7e22456ed4b3f882b81ab77d5f35b6ef2db87c1374042e0a86_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-network-operator@sha256:637168d333dbd5970715b98f97946e85bc71485824c4dab2de82154efb8a472b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-network-operator@sha256:abc6213b793b35a404eeec68d5667bd6e108879ee86a182fc6efe5efae463e1f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-network-operator@sha256:c7728b5165b2abdc9f63d3dd83c2894a9adc49a3e50a2c4c56662657c0e4562b_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-console@sha256:483a932e552796c74a6ff394233710beb516f42c9b964fc13b3276f52cf4f7fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-console@sha256:7c69be58deb42c078baaa9f8b4e90f327a38b79a3b00a24ddb104c6727fc8a7e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-console@sha256:afab7d8212ee932132217b76ba99cee7c44369283634021f9c6c1956f83c4c98_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-console@sha256:eeff56f6fe0956bbc6379bea152e65e6b98809db8e48022db5ef396094bfc25e_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-hyperkube@sha256:474953b990b02f9f7141ef2316e6e4dfb654fa970be893bb11b0be4a6651003a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-hyperkube@sha256:a3adda700381f8b2f22509e4ade1022d86244f2fc9d1f2d2158259ffedd3b516_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-hyperkube@sha256:bbdf4f84891e1774cca9e07037e17b40b09737a2bf7af8ad292ded95c3c458ff_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-hyperkube@sha256:c59ba2f520589740b92799483837a438208a352854391173e0a87c4e8c6906f9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:5be223aa82849a0f6b14c3fd581ee34b065d439b601a0bb1bcc2659a258afb39_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:7486da69bbcacaf43bea2cb8d681e556084aaccfd388e1ad4383cbba517d142b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-machine-config-operator@sha256:1bf04c081f10010a77c3bbdf098b48f94333138c0ed614be39594ccbf2c11a7b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +39 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:9c4a4471bb93ab11d255925535ff719742cafa8ae06d622b870133787a72abc3 (For s390x architecture) The image digest is sha256:80c287d6ee8baa959462ddb58f23c89cd4d37e54350813de09ef2b2704519057 (For ppc64le architecture) The image digest is sha256:0b087b1c8f1af8c2339fd40c57e2b15d3bb5c4c761ed04b6e67dc3b9fff7be19 (For aarch64 architecture) The image digest is sha256:e0c45710ebff1bcd72c694f3bac3de92074163aa1db4b7a03d1a81cb53b79888 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:0193
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/OCPBUGS-19658
- externalhttps://issues.redhat.com/browse/OCPBUGS-23483
- externalhttps://issues.redhat.com/browse/OCPBUGS-25988
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0193.json